Enhanced Multi-Factor Authentication Options
New MFA options including hardware keys, biometrics, and authenticator apps.

Protect your account with our comprehensive suite of enhanced multi-factor authentication options, designed to provide maximum security without compromising user experience.
The Passwordless Future Is Here
Passwords alone are no longer sufficient. With cyber threats evolving daily, multi-factor authentication has become essential for protecting your digital identity. We're excited to announce expanded MFA options that leverage the latest security technologies while remaining easy to use.
The passwordless authentication market is growing from $22.14 billion in 2025 to an expected $61.45 billion by 2032, reflecting the industry-wide shift toward more secure authentication methods. Gartner projects that by 2025, over 50% of workforce authentication transactions will be passwordless, and we're proud to be leading this transformation.
Comprehensive MFA Options
Hardware Security Keys: FIDO2/WebAuthn Support
Hardware security keys represent the gold standard in authentication security. Our platform now fully supports FIDO2 and WebAuthn standards, allowing you to use physical security keys for phishing-resistant authentication.
Why Hardware Keys?
- Phishing-Resistant: Impossible to trick users into providing credentials to fake websites
- Fast Authentication: Three times faster than traditional passwords
- No Shared Secrets: Cryptographic keys never leave your device
- Universal Compatibility: Works across all major browsers and platforms
- Long-Lasting: Hardware keys can last years without replacement
Supported Devices:
- YubiKey 5 Series
- Google Titan Security Keys
- Feitian ePass FIDO security keys
- Thetis FIDO U2F security keys
- Any FIDO2-certified security key
How It Works: Hardware keys use public-key cryptography. When you register a key, a unique cryptographic key pair is created. The public key is stored on our servers, while the private key remains securely on your hardware device. Authentication happens through a cryptographic challenge-response process that proves you possess the physical key without ever transmitting the private key itself.
Best Practices:
- Register multiple keys for redundancy
- Keep a backup key in a secure location
- Use keys with NFC for mobile device compatibility
- Consider keys with biometric capabilities for additional security
- Store keys separately from devices they protect
Biometric Authentication: Face ID and Fingerprint
Leverage the biometric sensors already built into your devices for seamless, secure authentication. Our biometric support works with Face ID, Touch ID, Windows Hello, and Android biometric systems.
Advantages:
- Convenience: Authenticate with a glance or touch
- Speed: Eight times faster than password plus traditional MFA
- Unique to You: Biometric data is nearly impossible to replicate
- On-Device Processing: Biometric data never leaves your device
- Accessibility: Easier for users with mobility or memory challenges
Security Architecture: We implement biometric authentication using WebAuthn, which means your actual biometric data never leaves your device. Instead, the authentication process uses cryptographic proofs that work with your device's secure enclave or trusted platform module (TPM). Your fingerprint or face data remains stored securely on your device, and we only receive confirmation that authentication succeeded.
Platform Support:
- iOS/iPadOS: Face ID and Touch ID on supported devices
- macOS: Touch ID on MacBook and Magic Keyboard
- Windows: Windows Hello facial recognition and fingerprint
- Android: Fingerprint and facial recognition on supported devices
Privacy Guarantees:
- Biometric data never transmitted over the network
- Authentication uses cryptographic tokens, not biometric templates
- Compliance with GDPR, CCPA, and biometric privacy regulations
- Users maintain complete control over biometric enrollment
- Option to disable biometrics at any time
Authenticator Apps: TOTP Support
Time-based One-Time Passwords (TOTP) provide a reliable, widely-supported MFA method that works offline and doesn't require specialized hardware.
How TOTP Works: When you enable TOTP authentication, you scan a QR code with your authenticator app. This establishes a shared secret between your account and the app. The app then generates time-synchronized six-digit codes that change every 30 seconds. You enter the current code when logging in to prove you have access to your registered device.
Recommended Authenticator Apps:
- Authy: Multi-device sync with encrypted backups
- Google Authenticator: Simple, reliable, widely used
- Microsoft Authenticator: Integrates with Microsoft ecosystem
- 1Password: Combines password management with TOTP
- Duo Mobile: Enterprise-grade with push notifications

Advantages:
- Works offline without network connectivity
- No dependency on SMS or phone service
- Supported on all smartphones and tablets
- Can be backed up for device migration
- Industry-standard implementation
Setup Process:
- Enable TOTP in your security settings
- Scan the QR code with your authenticator app
- Enter the six-digit verification code
- Save your backup codes in a secure location
- Confirm TOTP is active in your security settings
Backup Codes: Emergency Access
We provide backup codes as a safety net for situations where your primary MFA methods aren't available.
When to Use Backup Codes:
- Lost or damaged security key
- New phone without authenticator app
- Traveling without biometric-enabled devices
- Emergency access situations
- Device replacement or upgrades
Security Best Practices:
- Generate Fresh Codes: Create new codes after any use
- Secure Storage: Keep codes in a password manager or secure physical location
- Limited Use: Each code can only be used once
- Regeneration: Generate new codes if you suspect compromise
- Multiple Sets: Consider keeping backup codes in multiple secure locations
How Many Codes? We provide 10 single-use backup codes when you enable MFA. Once a code is used, it's immediately invalidated. You can generate new sets of codes at any time from your security settings.
The Technology: FIDO2 and WebAuthn
Understanding FIDO2
FIDO2 (Fast Identity Online 2) is an open authentication standard that enables passwordless and multi-factor authentication through public-key cryptography. It consists of two main components:
WebAuthn (Web Authentication API): A web standard that enables websites and applications to offer passwordless and multi-factor authentication using public-key cryptography. WebAuthn is supported by all major browsers including Chrome, Firefox, Safari, and Edge.
CTAP (Client to Authenticator Protocol): Enables external authenticators like security keys to communicate with devices over USB, NFC, or Bluetooth.
Quantum-Safe Security
In a significant 2025 development, FIDO2 and passkeys have become quantum-resistant. On April 24, 2025, IANA updated the CBOR Object Signing and Encryption (COSE) codelist to officially support post-quantum cryptographic (PQC) algorithms. This means our authentication system is prepared to resist threats from quantum computers, ensuring your accounts remain secure even as computing technology advances.
Industry Adoption
We're part of a growing movement toward more secure authentication:
- Nearly half (48%) of the top 100 websites now offer passkeys as a login method
- E-commerce platforms are driving passkey adoption, accounting for nearly half of all passkey authentications
- Major organizations have deployed hundreds of thousands of security keys to their workforce
- Consumer awareness is growing, with 53% recognizing stronger security and 54% appreciating greater convenience
Performance and User Experience
Speed Improvements
Our new MFA methods are significantly faster than traditional authentication:
- Passkey logins: 3x faster than passwords
- Compared to password + traditional MFA: 8x faster
- Biometric authentication: Sub-second authentication times
- Hardware keys: Tap and authenticate in under 2 seconds



Reduced Friction
We've designed our MFA implementation to be as seamless as possible:
- Contextual Prompts: Only request MFA when necessary
- Device Trust: Remember trusted devices for convenience
- Adaptive Authentication: Risk-based authentication that requires additional verification only when needed
- Multiple Methods: Choose the authentication method that works best for each situation
- Progressive Enrollment: Gradually guide users through MFA setup
Implementation and Rollout
Getting Started
Enabling MFA is straightforward:
- Navigate to Security Settings: Find MFA options in your account security settings
- Choose Your Method: Select from hardware keys, biometrics, authenticator apps, or multiple methods
- Follow Setup Instructions: Each method has guided setup with clear instructions
- Generate Backup Codes: Save backup codes in a secure location
- Test Your Setup: Verify everything works before completing setup
Organizational Rollout
For team administrators, we provide tools to manage MFA across your organization:
Admin Controls:
- Enforcement Policies: Require MFA for all team members
- Method Requirements: Specify which MFA methods are acceptable
- Grace Periods: Give users time to set up MFA before enforcement
- Reporting: Track MFA adoption across your organization
- Support Resources: Help team members enable and use MFA
Best Practices for Teams:
- Communicate the change well in advance
- Provide clear documentation and training
- Offer multiple authentication methods
- Designate internal champions to help others
- Monitor adoption and provide support
- Consider providing hardware keys to team members
Migration from Legacy MFA
If you're currently using SMS-based authentication, we encourage upgrading to more secure methods:
Why Move Beyond SMS:
- SMS is vulnerable to SIM swapping attacks
- Phone number portability creates security risks
- SMS doesn't work in areas without cellular coverage
- SMS is being deprecated by security standards
- Modern alternatives are more secure and convenient
Migration Path:
- Add a new MFA method (hardware key, biometric, or authenticator app)
- Test the new method thoroughly
- Remove SMS as your primary MFA method
- Keep backup codes updated
- Consider registering multiple MFA methods for redundancy
Security Considerations
Defense in Depth
MFA is one layer in our comprehensive security strategy:
- Encryption: All data encrypted in transit and at rest
- Session Management: Secure session handling with automatic timeouts
- Anomaly Detection: AI-powered detection of unusual authentication patterns
- Audit Logs: Comprehensive logging of all authentication events
- Regular Security Audits: Third-party penetration testing and security assessments
Compliance and Standards
Our MFA implementation meets or exceeds requirements for:
- NIST 800-63B: Digital identity guidelines
- PCI DSS: Payment card industry standards
- HIPAA: Healthcare information security
- SOC 2 Type II: Service organization controls
- GDPR: European data protection regulation
- CCPA: California consumer privacy act
- ISO 27001: Information security management
Threat Protection
Our MFA methods protect against:
- Phishing: Hardware keys and WebAuthn are phishing-resistant
- Credential Stuffing: Stolen passwords are useless without second factor
- Man-in-the-Middle: Cryptographic authentication prevents interception
- Brute Force: Rate limiting and account lockouts
- Social Engineering: Physical tokens can't be tricked out of users
- SIM Swapping: No reliance on phone numbers
Support and Resources
Documentation
Comprehensive guides available for:
- Setting up each MFA method
- Troubleshooting common issues
- Best practices for security
- Organizational deployment guides
- API documentation for developers
Getting Help
Support Channels:
- In-app help and guided setup
- Video tutorials for each method
- Live chat support for setup assistance
- Email support at security@tanqory.com
- Community forums for peer advice
Common Questions:
- What if I lose my security key?
- How do I set up MFA on multiple devices?
- Can I use different methods on different devices?
- What happens if my phone with authenticator app breaks?
- How do I help team members with MFA setup?
Looking Ahead
Future Enhancements
We're continuously improving our authentication capabilities:
Coming Soon:
- Passkey Sync: Sync passkeys across your devices
- Risk-Based Authentication: Adaptive MFA based on login context
- Behavioral Biometrics: Continuous authentication based on usage patterns
- Hardware Key Management: Centralized management for organizational hardware keys
Industry Leadership
We're committed to advancing authentication security:
- Active participation in FIDO Alliance
- Contributing to WebAuthn standards development
- Publishing security research and best practices
- Partnering with hardware key manufacturers
- Supporting emerging authentication technologies
Take Action Today
Security is a shared responsibility. Enable multi-factor authentication today to protect your account and data.
Recommended Setup:
- Primary: Hardware security key or biometric authentication
- Secondary: Authenticator app as backup
- Emergency: Backup codes stored securely
- Review: Check your security settings quarterly
Two factors are better than one. Multiple secure factors are even better.
For security questions, contact security@tanqory.com To report security issues, visit security.tanqory.com


